:art: modify travis yml for test coverage
Egg-Authz is an authorization middleware for Egg, it's based on https://github.com/casbin/node-casbin.
npm install koa-authz
// app/middleware/authz.js module.exports = require('koa-authz')
// config/config.default.js const { Enforcer } = require('casbin') module.exports = { middleware: [ 'authz' ], authz: { enable: true, newEnforcer: async() => { // load the casbin model and policy from files, database is also supported. const enforcer = await Enforcer.newEnforcer('authz_model.conf', 'authz_policy.csv') return enforcer } } }
The authorization determines a request based on {subject, object, action}, which means what subject can perform what action on what object. In this plugin, the meanings are:
subject: the logged-on user nameobject: the URL path for the web resource like “dataset1/item1”action: HTTP method like GET, POST, PUT, DELETE, or the high-level actions you defined like “read-file”, “write-blog”For how to write authorization policy and other details, please refer to the Casbin's documentation.
This project is under MIT License. See the LICENSE file for the full license text.